Skip to content
Activamente explotadaCVSS 8.4 · HIGH

CVE-2024-1708

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

Ver en NVD

Severidad

Puntaje: 8.4(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: HIGH
UI: REQUIRED
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-22

CISA KEV

Agregada al KEV: 2026-04-28
Fecha límite federal: 2026-05-12
Uso conocido en ransomware: Unknown
Acción requerida

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probabilidad de explotación (próx. 30 días): 0.8395 (84.0%)
Percentil: 99.3%
EPSS: 2026-05-06

Afecta

connectwise:screenconnect

Descripción técnica

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

Publicada: 21/2/2024, 16:15:50
Última modificación: 28/4/2026, 21:44:53

Referencias

InicioEventosBlogRecursosEquipo